The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leading to low impact on confidentiality. Integrity and availability are unaffected.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-05-26 18:16
Updated : 2026-07-24 11:10
NVD link : CVE-2026-44749
Mitre link : CVE-2026-44749
CVE.ORG link : CVE-2026-44749
JSON object : View
Products Affected
No product.
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
